A dangerous (but now-fixed) Sudo vulnerability allowed any local user to gain root privileges on Linux systems without requiring authentication. . Sudo is a Unix program that enables system admins to provide limited root privileges to normal users listed in the sudoers file, while at the same time keeping a log of their activity. It works on the Principle of Least Privilege where the program gives people just enough permissions to get their work done without compromising the system's overall security. . Sudo is a command-line utility in Unix-like systems that allows system administrators to grant specified users elevated access to run commands as the superuser or another user.. Sudo Vulnerability, Root Access, Linux Security, User Privileges. . Brittany Day
The last several weeks, as always, have brought a constant flow of security advisories. Perhaps not a torrent, but certainly more than a mere trickle. Most notable among these is the Linux kernel ptrace vulnerability, which allows local users to acquire root privileges.. . .. The last several weeks, as always, have brought a constant flow of security advisories. Perhaps not a torrent, but certainly more than a mere trickle. Most notable among these is the Linux kernel ptrace vulnerability, which allows local users to acquire root privileges. Next, there is a clever timing attack against OpenSSL that can reveal a site's private key and thus compromise all of its traffic. There is also the mysql configuration file vulnerability, whereby a malicious user can write out a file that will allow him to acquire full privileges; a buffer overflow and local root exploit in the venerable lpr print daemon; a buffer overflow and potential root exploit in the Mutt mail reader's IMAP code; and a glibc integer overflow that allows remote code execution via RPC. . Current security bulletins underscore urgent vulnerabilities within the Linux kernel, OpenSSL, and MySQL, necessitating prompt action.. Linux Kernel Security, OpenSSL Timing Attack, Mysql Threat, Buffer Overflow Exploits. . LinuxSecurity.com Team
The Computer Emergency Response Team has updated their advisory on the recent Kerberos buffer overflow vulnerabilities. Most vendors have updated their packages already to fix this vulnerability. "The most severe vulnerability allows remote intruders to gain root privileges . . .. The Computer Emergency Response Team has updated their advisory on the recent Kerberos buffer overflow vulnerabilities. Most vendors have updated their packages already to fix this vulnerability. "The most severe vulnerability allows remote intruders to gain root privileges on systems running services using Kerberos authentication. If vulnerable services are enabled on the Key Distribution Center (KDC) system, the entire Kerberos domain may be compromised. " . The Computer Emergency Response Team has updated their advisory on the recent Kerberos buffer overfl. computer, emergency, response, updated, their, advisory, recent, kerberos, buffer, overfl. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.